<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676717#M113180</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Same symptoms here upgrading from 9.0.5 to 9.1.3...&lt;/P&gt;&lt;P&gt;Did you find out what was the workaround ?&lt;/P&gt;&lt;P&gt;What did you do ?&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2024 10:48:52 GMT</pubDate>
    <dc:creator>emallinger</dc:creator>
    <dc:date>2024-02-06T10:48:52Z</dc:date>
    <item>
      <title>HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/658835#M111421</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have just upgraded to 9.1.1 and our HEC seems to have stopped working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Calling it from a simple PowerShell script worked the day before and running it now throws this error :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Unable to connect to the remote server&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;No connection could be made because the target machine actively refused it xxx.xxx.xxx.xxx:8088&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;So, headed over to the Forwarder where it should be listening, and the tokens do still exist in the Inputs.conf in "/opt/splunkforwarder/etc/apps/splunk_httpinput/local"&lt;/P&gt;&lt;P&gt;However, issuing the list command gives us the following :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;$SPLUNK_HOME/bin/splunk http-event-collector list -uri &lt;A href="https://localhost:8089" target="_blank" rel="noopener"&gt;https://localhost:8089&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Token Not Found&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;The HEC is Enabled in the Global Settings but we are also not seeing anything listening on Port 8088&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Splunk Enterprise on a Linux build.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 08:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/658835#M111421</guid>
      <dc:creator>C_Lawrence</dc:creator>
      <dc:date>2023-09-27T08:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676717#M113180</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Same symptoms here upgrading from 9.0.5 to 9.1.3...&lt;/P&gt;&lt;P&gt;Did you find out what was the workaround ?&lt;/P&gt;&lt;P&gt;What did you do ?&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 10:48:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676717#M113180</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2024-02-06T10:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676719#M113181</link>
      <description>&lt;P&gt;Found it :&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/SSL-enabled-inputs-stopped-receiving-data-after-upgrade-from-Splunk-version-8-x-to-version-9-x" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/SSL-enabled-inputs-stopped-receiving-data-after-upgrade-from-Splunk-version-8-x-to-version-9-x&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 11:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676719#M113181</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2024-02-06T11:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676721#M113182</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So sorry. I though I had update and resolved this message.&lt;/P&gt;&lt;P&gt;As I was trying to get logged in (it took a while!), you sent the other update. That was not the fix for me.&lt;/P&gt;&lt;P&gt;While I had a case open for while with Splunk, I cam across this fix :&lt;/P&gt;&lt;P&gt;On the Forwarder :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/opt/splunkforwarder/etc/system/local/server.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Add this Stanza :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[httpServer]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;mgmtMode = tcp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 11:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676721#M113182</guid>
      <dc:creator>C_Lawrence</dc:creator>
      <dc:date>2024-02-06T11:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676735#M113183</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yes, that's exactly what I did and that fixed the issue in my case :).&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 13:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Connection-Actively-Refused-after-upgrading/m-p/676735#M113183</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2024-02-06T13:10:52Z</dc:date>
    </item>
  </channel>
</rss>

